Live data from Hacker News

T-Mobile: Breach Exposed SSN/DOB of 40M+ People

krebsonsecurity.com

81–90 of 282 posts

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#81

No, the US has far more religious fundamentalists than the EU. They believe that such a system is tantamount to taking the Mark of the Beast, quoting Revelation 13:16-17: > And he causes all, the small and the great, and the rich and the poor, and the free men and the slaves, to be given a mark on their right hand or on their forehead, and he provides that no one will be able to buy or to sell, except the one who has…

This is just nonsense. Where are you coming up with this theory?

Everyone has an ssn already wouldn’t that qualify for the mark?

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#82
post #81

No, the US has far more religious fundamentalists than the EU. They believe that such a system is tantamount to taking the Mark of the Beast, quoting Revelation 13:16-17: > And he causes all, the small and the great, and the rich and the poor, and the free men and the slaves, to be given a mark on their right hand or on their forehead, and he provides that no one will be able to buy or to sell, except the one who has…

This is just nonsense. Where are you coming up with this theory? Everyone has an ssn already wouldn’t that qualify for the mark?

They fear that the ID, rather than being an easily stolen card, may one day become a chip that is implanted in the body... in the right hand or forehead. And that wouldn't be a sin in and of itself, but the Bible implies that Christians will need to commit apostasy and worship the Antichrist to receive this mark which will be necessary to function in society.

So imagine a dictator, or a tyrannical government (say China) who said you need to worship Xi Jinping to receive the chip implanted in your body for identification purposes. Something like that they speculate. And that if you don't worship Xi, you don't get the chip, and you can't buy or sell anything.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#83

The EU has a federated public key cryptography based identity system. The member states recognize identities issued by other member states, but there is no central system. In any case, the private key is stored on a plastic ID, which acts as a smart card and can be hooked up to a smartphone/PC for identity verification and document signing online. The key is only released with a PIN, and the databases online only sto…

The ID is not always on a plastic id card, for example BankID (at least the swedish variant) is eIDAS compliant and is instead an app where the identity is issued by your bank.

I have the ID card with smartcard capabilities too but I've never seen any place in sweden where they are used, but it's good to know I have it if I need to identify in the rest of europe.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#84
post #72

> If you’re a current T-Mobile customer, by all means change your account PIN as instructed. But regardless of which mobile provider you patronize, consider removing your phone number from as many online accounts as you can. Many online services require you to provide a phone number upon registering an account, but in many cases that number can be removed from your profile afterwards. > Why do I suggest this? Many on…

> Hmmm, I get why he says this, but what is the practical scenario here? We remove phone numbers from accounts after we make them? But doesn't that just mean we disable 2FA, making our accounts less secure and therefore more likely to be compromised by other means?

Encryption of sensitive data is freely available. When the data gets stolen, it would not contain the sensitive data, since that would be in a non-readable format. It is a liability for companies to store these incredibly large amounts of personal data in centralized locations.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#85
post #81

No, the US has far more religious fundamentalists than the EU. They believe that such a system is tantamount to taking the Mark of the Beast, quoting Revelation 13:16-17: > And he causes all, the small and the great, and the rich and the poor, and the free men and the slaves, to be given a mark on their right hand or on their forehead, and he provides that no one will be able to buy or to sell, except the one who has…

This is just nonsense. Where are you coming up with this theory? Everyone has an ssn already wouldn’t that qualify for the mark?

When has religion ever been consistent?

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#86
post #70

The EU has a federated public key cryptography based identity system. The member states recognize identities issued by other member states, but there is no central system. In any case, the private key is stored on a plastic ID, which acts as a smart card and can be hooked up to a smartphone/PC for identity verification and document signing online. The key is only released with a PIN, and the databases online only sto…

except that eIDAS is basically not in use in germany.

Well, Germany is not the entire EU. I have such card and it comes in handy from time to time, though the implementation could be much better.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#87

No, the US has far more religious fundamentalists than the EU. They believe that such a system is tantamount to taking the Mark of the Beast, quoting Revelation 13:16-17: > And he causes all, the small and the great, and the rich and the poor, and the free men and the slaves, to be given a mark on their right hand or on their forehead, and he provides that no one will be able to buy or to sell, except the one who has…

You're significantly overestimating the amount of pull that type of person has in the US anymore, while simultaneously dramatically (I can only assume willfully) misquoting that bible verse.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#88
post #7
post #3

Are SSNs stored in plain text?

Probably so, in this case. Here's a screenshot they uploaded as proof of the hack: https://pbs.twimg.com/media/E848JkGUUAIhIq5?format=jpg You can see that it's running Goldengate, software used to replicate Oracle or other databases. So it probably had all the DB credentials needed to just export the whole database.

> THERE IS NO RIGHT TO PRIVACY ON THIS SYSTEM.

Well at least they weren't lying.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#89
post #81

No, the US has far more religious fundamentalists than the EU. They believe that such a system is tantamount to taking the Mark of the Beast, quoting Revelation 13:16-17: > And he causes all, the small and the great, and the rich and the poor, and the free men and the slaves, to be given a mark on their right hand or on their forehead, and he provides that no one will be able to buy or to sell, except the one who has…

This is just nonsense. Where are you coming up with this theory? Everyone has an ssn already wouldn’t that qualify for the mark?

There are people who believe the Earth is flat and that Donald Trump won the 2020 election. Of course there are people who believe social security numbers are the mark of the beast. You can find dozens of conspiracy theorists making that claim with a simple Internet search. It's not even a rare conspiracy theory.

Re: T-Mobile: Breach Exposed SSN/DOB of 40M+ People

#90
post #81

No, the US has far more religious fundamentalists than the EU. They believe that such a system is tantamount to taking the Mark of the Beast, quoting Revelation 13:16-17: > And he causes all, the small and the great, and the rich and the poor, and the free men and the slaves, to be given a mark on their right hand or on their forehead, and he provides that no one will be able to buy or to sell, except the one who has…

This is just nonsense. Where are you coming up with this theory? Everyone has an ssn already wouldn’t that qualify for the mark?

This is absolutely a concern I have heard my entire life from many people in rural Colorado, and they are all dead serious about it.
Post reply on HN